Splunk Enterprise Security

What is the solution for real-time dataset to be ingested in Splunk Enterprise Security?


Thank you all in advance! Actually, I have built a lab environment (AWS) and installed the ES APP (Enterprise Security). Now, I am looking for a solution to have access to the required data (real-time) which can be used in ES. I tried to install the Eventgen and make it work, but it does not seem to be an easy procedure. Could you please provide me a straight forward solution.

0 Karma
Get Updates on the Splunk Community!

Maximize the Value from Microsoft Defender with Splunk

<P style=" text-align: center; "><span class="lia-inline-image-display-wrapper lia-image-align-center" ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

<FONT size="5"><FONT size="5" color="#FF00FF">Get the latest news and updates from the Splunk Community ...